{"id":"GHSA-xxrg-mg63-qfpj","summary":"Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability","details":"Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the javascript: scheme.\n\nThis results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step.\n\nAs of publication of this advisory, there is no fix.","aliases":["CVE-2025-30196"],"modified":"2025-03-19T23:21:48.500868Z","published":"2025-03-19T18:30:51Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-03-19T22:37:59Z","nvd_published_at":"2025-03-19T16:15:33Z","cwe_ids":["CWE-79"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30196"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/anchor-chain-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2025-03-19/#SECURITY-3529"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:anchorchain","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/anchorchain"},"versions":["1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-xxrg-mg63-qfpj/GHSA-xxrg-mg63-qfpj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}